2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46749MEDIUM6.5Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentica...
CVE-2023-48383HIGH7.5NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthen...
CVE-2023-52289HIGH7.5An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, explo...
CVE-2023-52288HIGH7.5An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, explo...
CVE-2023-51071MEDIUM6.5An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers ...
CVE-2023-51070HIGH7.5An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers ...
CVE-2023-51068MEDIUM5.4An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build...
CVE-2023-51067MEDIUM6.1An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Bui...
CVE-2023-51066HIGH8.8An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allo...
CVE-2023-51065HIGH7.5Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers...
CVE-2023-51064MEDIUM6.1QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerab...
CVE-2023-51063HIGH8.8QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site S...
CVE-2023-51062MEDIUM5.3An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0...
CVE-2023-51805MEDIUM6.5SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information ...
CVE-2023-51804HIGH7.5An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP bo...
CVE-2023-46943CRITICAL9.1An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generati...
CVE-2023-46942HIGH7.5Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain ...
CVE-2023-33472HIGH8.8An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authen...
CVE-2023-50072MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension ...
CVE-2023-48166HIGH7.5A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 al...
CVE-2023-49647HIGH7.8Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows befor...
CVE-2023-51698HIGH8.8Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vu...
CVE-2023-49801HIGH7.5Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issu...
CVE-2023-49099MEDIUM4.3Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with ...
CVE-2023-49098LOW3.5Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now